Latest CVE Feed
-
6.8
MEDIUMCVE-2017-12732
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrite that could lead to an arbitrary r... Read more
Affected Products : intelligent_platforms_proficy_hmi\/scada_cimplicity- EPSS Score: %0.25
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-8393
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.... Read more
- EPSS Score: %4.84
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4857
Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.11 and Splunk Light prior to 6.4.2 allows to redirect users to arbitrary web sites and conduct phishing att... Read more
Affected Products : splunk- EPSS Score: %0.17
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-9515
Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.... Read more
Affected Products : dozer- EPSS Score: %3.32
- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8142
The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and versions earlier than LON-AL00BC00B221 has a use after free (UAF) vulnerability. An attacker tricks a user... Read more
- EPSS Score: %0.20
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2284
Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : popup_maker- EPSS Score: %0.54
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10329
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.... Read more
Affected Products : photo_station- EPSS Score: %15.11
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12062
An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled.... Read more
Affected Products : mantisbt- EPSS Score: %0.71
- Published: Aug. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6497
main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.... Read more
- EPSS Score: %3.01
- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2017-9843
SAP NetWeaver AS ABAP 7.40 allows remote authenticated users with certain privileges to cause a denial of service (process crash) via vectors involving disp+work.exe, aka SAP Security Note 2406841.... Read more
- EPSS Score: %0.27
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4905
SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via unspecified vectors.... Read more
- EPSS Score: %1.73
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-17105
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cm... Read more
- EPSS Score: %91.75
- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2016-6037
IBM Rational Team Concert (RTC) is vulnerable to HTML injection. A remote attacker with project administrator privileges could send a project that contains malicious HTML code, which when the project is viewed, would be executed in the victim's Web browse... Read more
Affected Products : rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert- EPSS Score: %0.15
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-10831
Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : commercial_registration_electronic_authentication_software- EPSS Score: %0.18
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10795
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.... Read more
Affected Products : subrion- EPSS Score: %0.22
- Published: Jul. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9922
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpCompareR... Read more
- EPSS Score: %0.03
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9904
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!Rtl... Read more
Affected Products : xnview- EPSS Score: %0.28
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9882
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Block Data Move starting at FPX!FPX_GetScanDevicePropertyGroup+0x00... Read more
- EPSS Score: %0.21
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9880
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX+0x0000000000007236."... Read more
- EPSS Score: %0.21
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9863
An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a POST request to c... Read more
Affected Products : sunny_explorer sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_tripower_5000tl_firmware sunny_tripower_12000tl_firmware sunny_tripower_60_firmware +69 more products- EPSS Score: %0.25
- Published: Aug. 05, 2017
- Modified: Apr. 20, 2025